Vulnerability Database

291,049

Total vulnerabilities in the database

CVE-2014-4049

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

  • Published: Jun 18, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-4049
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.1
  • AV:N/AC:H/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
opensuse / opensuse 11.3 11.3.x
php / php 5.6.0-alpha5 5.6.0-alpha5.x
php / php 5.6.0-beta2 5.6.0-beta2.x
php / php 5.6.0-beta1 5.6.0-beta1.x
php / php 5.6.0-alpha3 5.6.0-alpha3.x
php / php 5.6.0-beta3 5.6.0-beta3.x
php / php 5.6.0-alpha2 5.6.0-alpha2.x
php / php 5.6.0-alpha1 5.6.0-alpha1.x
php / php 5.6.0-alpha4 5.6.0-alpha4.x
php / php 5.5.0 5.5.14
php / php 5.4.0 5.4.30
php / php 5.3.0 5.3.29
debian / debian_linux 8.0 8.0.x
debian / debian_linux 7.0 7.0.x